{"id":2115,"date":"2026-07-30T16:36:25","date_gmt":"2026-07-30T16:36:25","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2115"},"modified":"2026-07-30T16:36:25","modified_gmt":"2026-07-30T16:36:25","slug":"ai-powered-hacking-370-chrome-flaws-sonicwall-attacks-dns-hijacking-22-more-stories","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2115","title":{"rendered":"AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 30, 2026<\/span><\/span><span class=\"p-tags\">Hacking News \/ Cybersecurity News<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgNfPEjoHY1NDIrmCVPaZ_dmWbOk0MZwMlh6Odxpqfchn-5rOvsj4PhaBZs4LJvoj5iXhgbBTZzKCNYOPbblXU6kSnVNxEfQER6bNIuhROsSBTrhS6P_mPySTbAS5CvbYgu7lOANl0C6YuLR92om_sS_-9skmNqYT4BDmy_07cTMVj75vUUES70gPicrgGW\/s1700-e365\/threatsday.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A lot of security still comes down to trusting the wrong screen.<\/p>\n<p>This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder.<\/p>\n<p>Some defenses improved. The loose parts still got found first. Anyway, here&#8217;s the mess.<\/p>\n<div class=\"article-board\">\n <b\/><\/p>\n<p>The threats change every week. <span data-push-label=\"ThreatsDay Bulletin\" data-push-topic=\"threatsday bulletin:t, recap:i\">Subscribe, and we\u2019ll alert you<\/span> when each new ThreatsDay Bulletin is out.<\/p>\n<\/div>\n<div class=\"td-wrap\">\n<section aria-labelledby=\"threatsday-title\" class=\"td-section\">\n<ol class=\"td-timeline\" role=\"list\">\n<a name=\"more\"\/><\/p>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Phishing delivers XWorm<\/span><\/p>\n<p class=\"td-desc\">\n      A cybercrime group known as xplogs22 has been <a href=\"https:\/\/www.f6.ru\/blog\/xplogs22\/\" target=\"_blank\"> observed <\/a> targeting Russia and other CIS countries with phishing emails that deliver Xworm. The group, per F6, is believed to have been active since November 2023. Prior attacks mounted by the threat actors leveraged Formbook and Snake Keylogger, before switching to XWorm around July 2025. In recent months, Russian customers of the banking sector have also been targeted by an Android trojan called <a href=\"https:\/\/www.f6.ru\/blog\/lunaspy-android-research\/\" target=\"_blank\"> LunaSpy <\/a> as part of social engineering attacks. LunaSpy can capture camera streams, record audio and the screen, and collect sensitive data. The malware is disguised as an antivirus application to evade detection.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Custom ransomware targets Russia<\/span><\/p>\n<p class=\"td-desc\">\n      The financially motivated extortion group known as Toy Ghouls (aka Bearlyfy and Labubu) has targeted organizations in the Russian Federation, primarily in the manufacturing, financial services, retail, and technology sectors, with a custom ransomware family called GenieLocker since March 2026. According to Kaspersky, the group previously relied on third-party encryptors like RedAlert, LockBit, and Babuk. \u00abGenieLocker, apparently a custom design, upgrades their toolkit and reduces their reliance on third-party software,\u00bb Kaspersky <a href=\"https:\/\/securelist.com\/genielocker-ransomware-for-windows-linux-and-esxi\/120843\/\" target=\"_blank\">said<\/a>. In at least one case, initial access to the target environment was obtained via an OpenVPN connection originating from an external partner&#8217;s network, with the attackers likely exploiting the trusted relationship to breach the target, conduct reconnaissance, deliver additional tools for credential harvesting, and perform lateral movement via RDP and SSH to reach other Windows and Linux hosts. \u00abDuring the impact phase, the attackers encrypted files on the compromised Windows machines with the PE version of the GenieLocker ransomware,\u00bb Kaspersky said. \u00abOn the compromised Linux and ESXi servers, they stopped active virtual machines and encrypted their disks using the ELF version of GenieLocker.\u00bb Details of the activity were first highlighted by F6 in March 2026.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Crypto-stealing payloads deployed<\/span><\/p>\n<p class=\"td-desc\">\n      The malware loader known as CastleLoader, which has been previously used to deliver CastleStealer and a Python-based <a href=\"https:\/\/www.levelblue.com\/blogs\/spiderlabs-blog\/clickfix-is-now-hiring-from-job-platform-impersonation-to-python-based-rat-delivery\" target=\"_blank\">remote access trojan<\/a> (RAT) via ClickFix-style lures, has now been used to distribute two payloads tied to the Needle Stealer framework: a Rust-based desktop wallet spoofer, and a Golang-based malicious browser extension installer. Arctic Wolf <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/castleloader-new-campaigns-new-tooling-and-the-needlestealer-connection\/\" target=\"_blank\">said<\/a> it also identified a new shellcode loader variant spreading via digitally signed installers. The campaign has been codenamed Noidret. The introduction of these new tools is seen as an attempt to focus on cryptocurrency-specific targeting and establish browser-level persistence.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fileless WebDAV execution<\/span><\/p>\n<p class=\"td-desc\">\n      Speaking of ClickFix, CyberProof said it tracked a ClickFix variant that involves tricking victims into pasting a single command into the Windows Run dialog, which then communicates with a WebDAV endpoint and uses rundll32.exe to load a remote, non-DLL payload and call its first export by ordinal without having to leave any artifacts on disk. \u00abThe payload (gc.key, j.pm, or goog.ct) is a file served from the attacker WebDAV share and is not a standard DLL by extension,\u00bb CyberProof <a href=\"https:\/\/www.cyberproof.com\/blog\/clickfix-keeps-evolving-rundll32-ordinal-execution-over-webdav\/\" target=\"_blank\">said<\/a>. \u00abIt is invoked by rundll32.exe through ordinal #1, which runs its primary routine while keeping the export name off the command line.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake Claude guide spreads malware<\/span><\/p>\n<p class=\"td-desc\">\n      Victims searching Google for how to install Claude on a Mac are being served sponsored results that lead them to a weaponized claude.ai\/share conversation dressed up as an Apple Support install guide. The \u00abguide\u00bb instructs them to open Terminal and paste a single curl command, ultimately leading to execution of MacSync Stealer. \u00abMacSync is a six-stage kill chain, not a smash-and-grab,\u00bb Huntress <a href=\"https:\/\/www.huntress.com\/blog\/macsync-stealer-rat-reverse-engineering\" target=\"_blank\">said<\/a>. \u00abThe components are a thin zsh loader, a server-side AppleScript stealer that keeps the valuable logic off the endpoint and behind an api-key gate, a native Mach-O RAT for hands-on access, a separately signed helper built to steal a single TCC permission (Screen Recording), and a set of wallet-app trojans. Each stage sets up the ones that follow.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Malware, intrusions, and influence ops<\/span><\/p>\n<p class=\"td-desc\">\n      A Russian-speaking threat group is said to be behind an active campaign called Operation STANDOFF that combines commodity-malware distribution, a proxy-botnet that conscripts victims into relay infrastructure, targeted hands-on-keyboard intrusion of enterprise networks, and an AI-driven, multi-channel influence and engagement-manipulation capabilities under one roof. \u00abThe operation is materially more than a botnet,\u00bb VMRay Labs <a href=\"https:\/\/www.vmray.com\/execution-level-analysis-of-a-russian-speaking-multi-operator-intrusion-campaign-operation-standoff\/#elementor-toc__heading-anchor-8\" target=\"_blank\">said<\/a>. \u00abIt couples automated, scaled cybercrime with hands-on-keyboard, targeted intrusion and a coordinated influence capability, all on the same infrastructure and built by a common development team.\u00bb The influence apparatus uses networks of fake Telegram accounts and AI-generated personas to artificially boost the visibility of content, push commercial promotions, and drive traffic to gambling and fraud-adjacent services. The activity uses a pay-per-install (PPI) loader masquerading as software installers that delivers Raccoon Stealer, RedLine, Amadey, SmokeLoader, Socelars, Glupteba, and XMRig cryptocurrency miner, while a second, targeted operations layer relies on a bespoke, multi-operator command-and-control console through which human operators conduct hands-on-keyboard intrusions of selected victims.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fleet takeover flaw exposed<\/span><\/p>\n<p class=\"td-desc\">\n      Security researcher Eaton Zveare has disclosed details of a vulnerability in My Eicher, a fleet management system developed by the Volvo Group and Eicher Motors for Indian commercial vehicle customers, that enabled the discovery of unauthenticated internal and. admin APIs that could be exploited to gain high-level access to systems and even enable account takeover. \u00abAccount takeover made it possible to gain control over a person&#8217;s (or company&#8217;s) entire fleet, which could consist of hundreds of vehicles,\u00bb Zveare <a href=\"https:\/\/eaton-works.com\/2026\/07\/27\/my-eicher-hack\/\" target=\"_blank\">said<\/a>. Following responsible disclosure on November 3, 2025, the issue was addressed at some point by November 20.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI agents automate exploitation<\/span><\/p>\n<p class=\"td-desc\">\n      A Chinese-speaking threat actor has been carrying out an AI-enabled autonomous hacking campaign, targeting infrastructure using seven vulnerabilities in Langflow (CVE-2026-33017), n8n (CVE-2026-21858, CVE-2025-68613), Citrix NetScaler (CVE-2026-3055), Apache Tomcat (CVE-2026-34486), Marimo Notebook (CVE-2026-39987), Palo Alto Networks PAN-OS (CVE-2026-0300), and Microsoft Windows IKE Extensions (CVE-2026-33824). The actor, operating under the aliases knaithe and KnYuan, has leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator, while orchestrating the operation through Telegram to enumerate targets, source exploit tools, and initiate attacks without human intervention. \u00abHermes Agent provided orchestration (terminal access, Telegram-based command and control, and the skills system) while DeepSeek served as the reasoning engine for code generation, vulnerability assessment, target selection and decision-making,\u00bb Unit 42 <a href=\"https:\/\/unit42.paloaltonetworks.com\/autonomous-ai-cyber-attack-campaign\/\" target=\"_blank\">said<\/a>. Additionally, the threat actor is said to have used Claude Code, Codex, and Qwen Code in a limited capacity. \u00abWhen initial exploitation failed due to the target environment&#8217;s restrictive configurations, their Hermes Agent autonomously conducted searches for known critical-severity Common Vulnerabilities and Exposures (CVEs),\u00bb Unit 42 said. \u00abIt initially surveyed 10 product families, scanning GitHub for trending proofs of concept (PoCs) and prioritizing vulnerabilities by attack surface.\u00bb\n    <\/p>\n<\/p><\/div>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiJQscyCT9_oDLrhPakZOgSpvWbDAgr3hfaPyooh49rh4lzsACvfrnTF42bqE7MF7-4g_u_NbFOeKfwe2X2j4hNhhW91PO-qAgfG9yThmI6stY74NOqe8Dg18dcI39DnTXmHWRed4QlskG2VR_FEifij6L3NgMaSO0I-fWgYNzqhxNQngqT9P3z6XaWWmVT\/s1700-e365\/tele.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiJQscyCT9_oDLrhPakZOgSpvWbDAgr3hfaPyooh49rh4lzsACvfrnTF42bqE7MF7-4g_u_NbFOeKfwe2X2j4hNhhW91PO-qAgfG9yThmI6stY74NOqe8Dg18dcI39DnTXmHWRed4QlskG2VR_FEifij6L3NgMaSO0I-fWgYNzqhxNQngqT9P3z6XaWWmVT\/s1700-e365\/tele.png\" alt=\"\" border=\"0\" data-original-height=\"693\" data-original-width=\"1585\"\/><\/a><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Trusted access fuels cryptomining<\/span><\/p>\n<p class=\"td-desc\">\n      Details have emerged about a covert Linux XMRig campaign that exploits trusted access, and weaponizes Pluggable Authentication Modules (PAM) to create a forensic smokescreen and deploy a highly customized XMRig botnet implant. \u00abInitial access was achieved by exploiting a trusted third-party relationship, highlighting critical supply chain risks,\u00bb Group-IB <a href=\"https:\/\/www.group-ib.com\/blog\/xmrig-covert-linux-pam-abuse\/\" target=\"_blank\">said<\/a>. \u00abThe threat actor escalated to root access, but weaponised the pam_rootok policy to seamlessly impersonate multiple low-privileged users to create a forensic smokescreen designed to confuse incident responders and establish a &#8216;hydra-like&#8217; redundant persistence across unmonitored accounts.\u00bb The campaign is characterized by efforts to actively suppress system visibility by disabling logging services and removing authentication logs to blind standard file-based monitoring. The campaign was first observed in March 2026.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake recruiter delivers stealer<\/span><\/p>\n<p class=\"td-desc\">\n      Threat actors are masquerading as recruiters and trucking victims into installing a malicious application disguised as an AI meeting tool called Relay. The malware targets both macOS and Windows users, and attempts to steal sensitive data including browser credentials, wallet-related information, Keychain data, and Telegram sessions, per <a href=\"https:\/\/slowmist.medium.com\/threat-intelligence-job-scam-alert-interview-software-used-to-deliver-an-info-stealing-malware-37f018877e4c\" target=\"_blank\">SlowMist<\/a>.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">900,000 customers affected<\/span><\/p>\n<p class=\"td-desc\">\n      Australian energy company Origin Energy <a href=\"https:\/\/www.originenergy.com.au\/about\/investors-media\/further-update-on-data-security-incident\/\" target=\"_blank\">said<\/a> it completed the initial phase of its review into a security incident that took place earlier this month, <a href=\"https:\/\/www.originenergy.com.au\/update-july-2026\/\" target=\"_blank\">finding<\/a> that \u00abthe information of approximately 900,000 current and former customers was accessed.\u00bb The information accessed may include name, address, date of birth, phone number, last four digits of a credit card, or the BSB and last three digits of a bank account, and account details.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Healthcare SaaS accounts targeted<\/span><\/p>\n<p class=\"td-desc\">\n      Health-ISAC is warning of an increase in successful attacks conducted by <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/07\/13\/defending-saas-based-applications-against-shinyhunters-oauth-abuse\/\" target=\"_blank\">ShinyHunters<\/a>. \u00abThe group appears to prioritize identity compromise and SaaS access over traditional ransomware deployment,\u00bb it <a href=\"https:\/\/health-isac.org\/shiny-hunters-impact-to-health-sector-and-recommended-mitigation-strategies\/\" target=\"_blank\">said<\/a>. \u00abThe operational pattern described in recent incident reporting aligns to a repeatable chain: vishing (voice social engineering) \u2192 helpdesk\/MFA reset or device re-enrollment \u2192 Microsoft Entra (or Okta\/Google) SSO account takeover \u2192 pivot into connected SaaS platforms \u2192 rapid data exfiltration for extortion leverage. Even when victim statements indicate limited operational impact, the described tradecraft is the key defensive lesson. SSO is the control plane, and ShinyHunters&#8217; leverage is created through data theft at cloud scale.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Supply chain defenses tightened<\/span><\/p>\n<p class=\"td-desc\">\n      GitHub has <a href=\"https:\/\/github.blog\/security\/supply-chain-security\/disrupting-supply-chain-attacks-on-npm-and-github-actions\/\" target=\"_blank\">laid out<\/a> the various steps it has taken to harden the supply chain at various stages and combat attacks that target weaknesses in package repositories and CI\/CD systems for malware propagation. Some of these include: (1) npm adding preventive account protection for high-impact accounts, (2) safer pull_request_target defaults for GitHub Actions checkout, (3) better controls over who and what triggers GitHub Actions workflows, (4) read-only Actions cache for untrusted triggers, (5) support for CircleCI in npm trusted publishing, (6) Action workflow network firewall, (7) staged publishing for npm, (8) default package cooldown for Dependabot version updates, (9) self-service credential revocation for incident response, and (10) expanded credential revocation API support.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Seven critical Chrome flaws fixed<\/span><\/p>\n<p class=\"td-desc\">\n      In an update <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/07\/stable-channel-update-for-desktop_0887107924.html\" target=\"_blank\">released<\/a> on July 29, 2026, Google shipped patches to address 370 flaws in its Chrome browser, including seven that are rated critical in severity (from CVE-2026-17650 through CVE-2026-17656). Of these, 349 flaws were reported by Google itself, with the tech giant noting that the bugs were detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL. None of the patched vulnerabilities have been flagged as actively exploited. The fixes are available in versions 151.0.7922.71\/.72 for Windows and Mac and 151.0.7922.71 for Linux. Google has addressed over 1,800 vulnerabilities in Chrome since the beginning of the year.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Edge devices need forensic visibility<\/span><\/p>\n<p class=\"td-desc\">\n      The U.K. National Cyber Security Centre (NCSC) has urged network device manufacturers to help incident response teams by making it easier to gather evidence after a compromise. \u00abForensic observability is particularly important for edge devices such as firewalls, VPN gateways and other network appliances,\u00bb NCSC <a href=\"https:\/\/www.ncsc.gov.uk\/blogs\/making-forensic-observability-the-norm-for-network-devices\" target=\"_blank\">said<\/a>. \u00abThese systems often sit at trust boundaries and are increasingly targeted by sophisticated threat actors. Forensic observability means giving defenders reliable ways to understand what a device is doing, what it has done and whether it can still be trusted after an incident. This includes telemetry, logging, configuration state, and the ability to collect forensic data from both memory and data at rest. Manufacturers should provide supported mechanisms for gathering the evidence needed to investigate incidents, assess impact, and restore trust in affected systems.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Phishing pages built in real time<\/span><\/p>\n<p class=\"td-desc\">\n      Barracuda has revealed that LogoKit has evolved from a standard phishing kit into a \u00abreal-time deception platform\u00bb capable of building customized phishing pages for each victim. \u00abLogoKit has moved beyond static fake login pages, such as pre-built replicas of popular brands, to the creation and use of real-time, highly personalized phishing experiences,\u00bb it <a href=\"https:\/\/blog.barracuda.com\/2026\/07\/29\/logokit-phishing-service-real-time-deception-platform\" target=\"_blank\">said<\/a>. \u00abThe platform uses legitimate commercial web services to recreate a victim&#8217;s corporate login experience, making phishing attacks more convincing and harder to detect. Every victim effectively receives a uniquely branded phishing page, making generic indicators of compromise harder to identify.\u00bb This involves capturing a real-time screenshot of the victim&#8217;s legitimate website and building phishing pages tailored to them. LogoKit uses the commercial Thum.io service to \u00abcreate full, legitimate website screenshots for the phishing background and Clearbit to add legitimate brand logos.\u00bb The attackers also rely on legitimate services, including Google Favicon, ImageKit and Microlink APIs, to dynamically load authentic logos and website imagery in real-time. LogoKit campaigns use phishing emails bearing warnings about passwords or delivery failures and timesheet updates to direct victims to the fake pages.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Exploitation accelerates in 2026<\/span><\/p>\n<p class=\"td-desc\">\n      A new analysis from VulnCheck has revealed that despite a significant uptick in vulnerability discovery and disclosure, 23.43% of known exploited vulnerabilities (KEVs) showed evidence of exploitation on or before the day the CVE was published. \u00abAt the same time, vulnerabilities appear to be being exploited faster, with the median time from CVE publication to KEV falling from 120 days in 2025 to 80 days during the first half of 2026,\u00bb VulnCheck <a href=\"https:\/\/www.vulncheck.com\/blog\/state-of-exploitation-1h-2026\" target=\"_blank\">said<\/a>. \u00abOf 1,061 vulnerabilities attributed to AI-assisted discovery, only 14, or 1.3%, have been confirmed as exploited in the wild, roughly matching the overall exploitation rate of all vulnerabilities in the first six months of the year.\u00bb The top technology categories being targeted by exploitation activity include CMS systems, network edge devices, operating systems, server software, and AI infrastructure (e.g., Langflow, Majordomo, lollms, LiteLLM, and dify).\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Credential stuffing hits SonicWall<\/span><\/p>\n<p class=\"td-desc\">\n      An active, broad, and opportunistic credential stuffing campaign has been observed since July 25, 2026, resulting in successful unauthorized logins to SonicWall VPN and firewall accounts. To date, 92 unique user accounts across 30 organizations have been impacted. \u00abThe activity stems from five IPs and relies on infrastructure hosted on DigitalOcean to compromise numerous, seemingly unrelated organizations,\u00bb Huntress <a href=\"https:\/\/www.huntress.com\/blog\/sonicwall-credential-stuffing-campaign\" target=\"_blank\">said<\/a>. \u00abCurrent telemetry indicates this is an automated credential validation attack, consistent with similar campaigns targeting SonicWall VPNs throughout 2025 and 2026.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Threat actors get new names<\/span><\/p>\n<p class=\"td-desc\">\n      Google Threat Intelligence Group (GTIG) <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/updated-cyber-threat-actor-naming-system\/\" target=\"_blank\">said<\/a> it will be rolling out a unified naming schema for tracking threat actors as part of its effort to standardize tracking across platforms and public reporting. \u00abThe new naming convention aligns with industry standard threat actor naming systems,\u00bb GTIG said. To that end, the new schema utilizes a cryptonym-based approach employing two-word combinations for each distinct threat actor, similar to those adopted by CrowdStrike (e.g., Mustang Panda) and Microsoft (e.g., Twill Typhoon). The first word is a term chosen to represent the specific actor, while the second word categorizes threat clusters by motivation, attribution, or activity type. Going forward, APT44 (aka Sandworm) will be referred to as Sandworm Relic, where Relic is the category name for threat actors of Russian origin. Similarly, those from China will be grouped under Castle, Iran under Ion, North Korea under Neptune, and cybercriminal gangs under Comet. GTIG said it will continue to use UNC (or uncategorized) for threat clusters that are still in the early stages of investigation.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Hidden desktop hijacks sessions<\/span><\/p>\n<p class=\"td-desc\">\n      A new remote access trojan (RAT) called MedusaHVNC is being sold as malware-as-a-service (MaaS), per BlackFog. The malware embeds a hidden virtual network computing (HVNC) module that opens a browser on a separate Windows desktop that&#8217;s out of sight of the victim. \u00abThe browser still runs on the victim&#8217;s device, so it can load an existing profile, including cookies and session state,\u00bb BlackFog <a href=\"https:\/\/www.blackfog.com\/medusahvnc-a-hidden-desktop\/\" target=\"_blank\">said<\/a>. \u00abThis gives the operator access to live, logged-in sessions while the activity continues to come from the victim&#8217;s usual machine.\u00bb The seller lists Chrome, Edge, Brave, Firefox, and Telegram as supported applications. The malware uses a 5-stage infection chain. It begins when the legitimate \u00abwscript.exe\u00bb binary executes a JavaScript launcher, which then sets off the subsequent steps, including dropping additional payloads and using AutoIT to decrypt and launch MedusaHVNC, which then communicates with an external server to exfiltrate data.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">DNS hijack exposed credentials<\/span><\/p>\n<p class=\"td-desc\">\n      CubePilot has announced an operational disruption stemming from a DNS hijacking attack. Unknown threat actors are said to have gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercept traffic intended for internal systems. The threat actors also obtained TLS certificates covering all cubepilot.org subdomains. \u00abThe certificates obtained by the attacker covered every cubepilot.org subdomain, so credentials entered on any of our services on 24 July may have been captured &#8211; the portal and the forum included,\u00bb CubePilot <a href=\"https:\/\/cubepilot.com\/security-notice\/\" target=\"_blank\">said<\/a>. \u00abIf you used the same password anywhere else, change it there now.\u00bb CubePilot has since regained control of its domains and revoked the fraudulently issued certificates.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Spear-phishing delivers SpyGlace<\/span><\/p>\n<p class=\"td-desc\">\n      The threat actor known as APT-C-60 has continued to target Japanese organizations with spear-phishing emails to deliver SpyGlace malware. \u00abWhile several changes have been identified, such as a shift in infrastructure from Bitbucket to GitHub and updates to the malware itself, many characteristics remain consistent, including the abuse of legitimate services and the behavior of the malware,\u00bb JPCERT\/CC <a href=\"https:\/\/blogs.jpcert.or.jp\/en\/2025\/11\/APT-C-60_update.html\" target=\"_blank\">said<\/a> late last year. As of 2026, the spear-phishing emails contain a Proton Drive link to trick recipients into downloading a RAR archive containing a LNK file, which then deploys SpyGlace by downloading an intermediate payload from jsDelivr. \u00abBy using legitimate services, the threat actor may be attempting to make communications and downloads appear to be normal access,\u00bb JPCERT\/CC <a href=\"https:\/\/blogs.jpcert.or.jp\/en\/2026\/07\/apt-c-60_2026.html\" target=\"_blank\">said<\/a>.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI agent validates exploitable flaws<\/span><\/p>\n<p class=\"td-desc\">\n      Google has launched a preview of CodeMender, an AI agent designed to scan codebases for security flaws, confirm they are exploitable and eliminate false positives, and generate fixes for developers to review. The tool supports C\/C++, Go, Java, Python, Ruby, Rust, and TypeScript. \u00abThe agent goes beyond static code-pattern analysis by simulating an attack with exploit code it builds and runs in an isolated, customer-managed sandbox,\u00bb Google <a href=\"https:\/\/cloud.google.com\/blog\/products\/identity-security\/find-and-fix-software-vulnerabilities-with-codemender\" target=\"_blank\">said<\/a>. \u00abThe agent uses this proof-of-concept exploit to verify that the security flaw poses a legitimate risk. This critical verification phase allows your security practitioners and developers to prioritize validated risks by eliminating false positives.\u00bb CodeMender will add support for third-party frontier models later this year.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">4,340 extremist URLs flagged<\/span><\/p>\n<p class=\"td-desc\">\n      Europol said it supported an action targeting nihilistic violent extremist content online between June and July 2026 with an aim to disrupt The Com online ecosystem and restrict propaganda dissemination. The agency and its partners have flagged 4,340 \u00abhorrific\u00bb URLs linked to The Com for removal. Belgium, Finland, Hungary, Ireland, Luxembourg, Netherlands, Portugal, Spain, and Sweden participated in the effort. \u00abGroups affiliated with The Com recruit members and groom victims on social media, messaging apps, and gaming platforms to engage in self-harm, animal torture, violent attacks, and the production of child sexual abuse material,\u00bb Europol <a href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/europol-led-action-against-nihilistic-violent-extremist-network-com\" target=\"_blank\">said<\/a>. \u00abThey distribute propaganda on accessible platforms to attract young individuals, funnelling potential members and victims into private forums and chat rooms where radicalisation and victimisation occur. Victims are typically coerced into remaining under the perpetrators&#8217; influence through (s)extortion.\u00bb Members of the loose-knit collective also participate in cybercrime, extortion, doxxing, swatting, real-life shootings, stabbings, and other physical violence.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake games deliver Amatera<\/span><\/p>\n<p class=\"td-desc\">\n      Fake downloads of games, mods, cracks, and software are being used to spread RenPy Loader (aka RenEngine Loader). \u00abOnce installed, the loader starts a complex, multi-stage infection chain that abuses MSBuild and the EtherHiding technique before ultimately delivering Amatera Stealer,\u00bb Malwarebytes <a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intel\/2026\/07\/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding\" target=\"_blank\">said<\/a>. \u00abRenPy Loader has also been observed delivering other malware, including Hijack Loader and Lumma Stealer, showing that the final payload can vary between campaigns.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<\/ol>\n<\/section>\n<\/div>\n<p>Most failures stay quiet until someone relies on them.<\/p>\n<p>A login works. A partner is trusted. A tool behaves as expected. Then one assumption turns out to be doing all the security work.<\/p>\n<p>That is the part worth checking before next week finds it first.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 30, 2026Hacking News \/ Cybersecurity News A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2116,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[189,24,182,1112,11,2295,1014,2538,187],"class_list":["post-2115","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-aipowered","tag-attacks","tag-chrome","tag-dns","tag-flaws","tag-hacking","tag-hijacking","tag-sonicwall","tag-stories"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2115"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2115\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2116"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}